CVE-2015-3660
published 2015-07-03CVE-2015-3660: Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
1.75%
75.6th percentile
Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | safari | <= 6.2.6 | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari | — | — |
| apple | safari_8.0.7_safari_7.1.7_and_safari | — | — |
| nokogiri | nokogiri | >= 1.6.0 < 1.6.7.1 | 1.6.7.1 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
ghsa5.0MEDIUM
osv4.3MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3874-c4vv-qxvf: Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6
ghsa_unreviewed·2022-05-17
CVE-2015-3660 [MEDIUM] CWE-79 GHSA-3874-c4vv-qxvf: Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6
Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.
GHSA
Nokogiri subject to DoS via libxml2 vulnerability
ghsa·2018-08-21·CVSS 5.0
CVE-2015-5312 [MEDIUM] CWE-400 Nokogiri subject to DoS via libxml2 vulnerability
Nokogiri subject to DoS via libxml2 vulnerability
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 (as used in nokogiri before 1.6.7.1) does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
OSV
CVE-2015-3660: Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6
osv·2015-07-03·CVSS 4.3
CVE-2015-3660 [MEDIUM] CVE-2015-3660: Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6
Cross-site scripting (XSS) vulnerability in the PDF functionality in WebKit in Apple Safari before 6.2.7, 7.x before 7.1.7, and 8.x before 8.0.7 allows remote attackers to inject arbitrary web script or HTML via a crafted URL in embedded PDF content.
Red Hat
libxml2: CPU exhaustion when processing specially crafted XML input
vendor_redhat·2015-12-01·CVSS 5.0
CVE-2015-5312 [MEDIUM] libxml2: CPU exhaustion when processing specially crafted XML input
libxml2: CPU exhaustion when processing specially crafted XML input
The xmlStringLenDecodeEntities function in parser.c in libxml2 before 2.9.3 does not properly prevent entity expansion, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted XML data, a different vulnerability than CVE-2014-3660.
A denial of service flaw was found in libxml2. A remote attacker could provide a specially crafted XML or HTML file that, when processed by an application using libxml2, would cause that application to use an excessive amount of CPU.
Package: libxml2 (Red Hat Enterprise Linux 5) - Will not fix
Package: libxml2 (Red Hat JBoss Enterprise Web Server 2) - Will not fix
Apple
CVE-2015-3660: Safari 8.0.7, Safari 7.1.7, and Safari 6.2.7
vendor_apple·CVSS 4.3
CVE-2015-3660 [MEDIUM] CVE-2015-3660: Safari 8.0.7, Safari 7.1.7, and Safari 6.2.7
Apple Security Update: About the security content of Safari 8.0.7, Safari 7.1.7, and Safari 6.2.7
Product: Safari 8.0.7, Safari 7.1.7, and Safari
Version: 6.2.7
CVE: CVE-2015-3660
Component: CVE-ID
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.apple.com/archives/security-announce/2015/Jun/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00054.htmlhttp://support.apple.com/kb/HT204950http://www.securityfocus.com/bid/75494http://www.securitytracker.com/id/1032754http://lists.apple.com/archives/security-announce/2015/Jun/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2016-03/msg00054.htmlhttp://support.apple.com/kb/HT204950http://www.securityfocus.com/bid/75494http://www.securitytracker.com/id/1032754
2015-07-03
Published